Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-30 Thread Toby Blake
> On 30 Jun 2016, at 16:53, Russ Allbery wrote: > > Toby Blake writes: > >> Hi Russ, when you say "the CrackLib code in there is suspect", do you >> mean in the current krb5-strength? If so, can you provide details? >> Suspect, to the extent that it should not be used? Should it be built >> a

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-30 Thread Renata Maria Dart
Hi to Russ and Hank, we were able to resolve our problem...it was a leftover solaris file that needed to be replaced. Thanks for all the extra insight on cracklib, Renata some On Wed, 29 Jun 2016, Russ Allbery wrote: >"Henry B (Hank) Hotz, CISSP" writes: > >> Ah! Then it?s a question for Ru

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-30 Thread Russ Allbery
Toby Blake writes: > Hi Russ, when you say "the CrackLib code in there is suspect", do you > mean in the current krb5-strength? If so, can you provide details? > Suspect, to the extent that it should not be used? Should it be built > against a newer cracklib? Note that we're using it with MIT

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-30 Thread Toby Blake
> On 30 Jun 2016, at 01:52, Russ Allbery wrote: > > "Henry B (Hank) Hotz, CISSP" writes: > >> Ah! Then it’s a question for Russ Allbery or Alf Wachsmann. you need >> their email addresses? > > I don't think SLAC was using krb5-strength. (Although maybe now would be > a good time to take a lo

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-29 Thread Russ Allbery
"Henry B (Hank) Hotz, CISSP" writes: > Ah! Then it’s a question for Russ Allbery or Alf Wachsmann. you need > their email addresses? I don't think SLAC was using krb5-strength. (Although maybe now would be a good time to take a look at it? It was working with the version of Heimdal Stanford ma

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-29 Thread Henry B (Hank) Hotz, CISSP
Ah! Then it’s a question for Russ Allbery or Alf Wachsmann. you need their email addresses? > On Jun 29, 2016, at 5:22 PM, Jeffrey Altman > wrote: > > On 6/29/2016 6:39 PM, Renata Maria Dart wrote: >> >> >> Hi, we recently upgraded our heimdal servers from solaris to linux >> RHEL6 and from

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-29 Thread Jeffrey Altman
On 6/29/2016 6:39 PM, Renata Maria Dart wrote: > > > Hi, we recently upgraded our heimdal servers from solaris to linux > RHEL6 and from heimdal 1.4.1 to 1.6.99. In the process we seem to > have lost the ability for password changes to update > /var/heimdal/kpasswdd.history. Also, I believe the